← Back to list

The Report Nobody Hunted | Fiive Eyes

A threat intelligence team producing accurate reports and a hunting team defending the network are not the same as a security program that…

Fiive Eyes · 2026-07-30 08:28 · 0 claps · 4.2 min read
#cybersecurity #incident-response #information-security #cyber-defense #enterprise-security
Open on Medium ↗
Wiki topics: 🔒 · Cybersecurity

The Report Nobody Hunted | Fiive Eyes

A threat intelligence team producing accurate reports and a hunting team defending the network are not the same as a security program that works. The gap between the two — where a finding sits in a document nobody was required to act on — is where the actual breach lives.

2,000+ Organizations ultimately confirmed affected by the 2023 MOVEit Transfer mass-exploitation campaign — many compromised well after a patch and public indicators already existed

60M+ Individuals whose data was ultimately exposed across the MOVEit breach’s long tail, a number that kept climbing for months after the initial disclosure

2024 Year Cisco Talos documented ArcaneDoor, a state-linked campaign targeting edge network devices chosen specifically for their limited built-in logging

One-Way The direction most threat intelligence still flows inside a typical organisation — from a report into a document, with no structural path back into operations

Knowing and acting are not the same capability

Most mature security organisations now have both a threat intelligence function and a threat hunting or security operations function, and it is tempting to treat the existence of both as evidence that the underlying problem — finding threats before they cause damage — has been structurally addressed. It has not. Intelligence and operations are, in most environments, two separate disciplines with separate tools, separate reporting lines, and no reliable mechanism connecting what one discovers to what the other does about it. A threat intelligence report can be accurate, timely, and specific, and still change nothing, because producing the finding and acting on the finding are treated as two different jobs, handed off through email, a ticketing system, or a quarterly briefing rather than a closed operational loop.

When the patch existed and the compromise kept spreading anyway

The 2023 mass exploitation of MOVEit Transfer, a widely used managed file transfer product, by the Cl0p ransomware group is one of the clearest illustrations of this gap at scale. The vulnerability was disclosed, a patch was released, and indicators of compromise were published rapidly by the vendor and multiple security researchers. None of that stopped the breach from continuing to grow for months. More than two thousand organisations were ultimately confirmed affected, and the number of individuals whose data was exposed climbed past sixty million as the long tail of the campaign played out — not primarily because organisations lacked access to the relevant intelligence, but because knowing a vulnerability existed and having a patch available is a different organisational action from actually hunting your own environment for signs that it had already been exploited before the patch went in. Many affected organisations had the intelligence. Comparatively few had a structural process that automatically translated “here is a new indicator” into “here is an active hunt running against our own systems right now.”

When the target was chosen specifically to defeat a static report

In April 2024, Cisco’s Talos threat intelligence group disclosed ArcaneDoor, a sophisticated, state-linked espionage campaign that had been targeting edge network devices — the routers, firewalls, and VPN appliances sitting at the perimeter of government and critical infrastructure networks. The choice of target was deliberate in a specific and instructive way: these devices typically retain limited logging by design, meaning that even once the campaign was discovered and its indicators published, organisations without an active, continuous hunting capability already instrumented against exactly this class of device had comparatively little historical evidence left to search through. A static intelligence report listing known indicators is most useful against a threat that leaves conventional traces in conventional places. A sophisticated actor choosing infrastructure specifically because it doesn’t retain much evidence has, in effect, designed their operation to defeat exactly the kind of one-time, backward-looking hunt a report alone can trigger — and can only be reliably caught by hunting that was already running, continuously, before the campaign was ever identified.

Why the loop has to run in both directions

The gap this module addresses is not solved by simply making intelligence faster or hunting teams larger. It requires the two functions to be structurally connected in both directions: every relevant piece of intelligence should automatically seed a specific, actionable hunting hypothesis against an organisation’s own environment, not wait for a human to read a report and decide to act on it — and every discovery a hunting team makes, including the false positives and the near-misses, should automatically flow back to refine the next round of intelligence, rather than staying siloed in whichever team happened to find it. Most security programs have neither direction of this loop built structurally. Many have only the first, and even that one usually depends on a person remembering to make the connection.

The architecture required

A genuine closed-loop capability treats intelligence and operations as one continuous system rather than two departments that occasionally share documents. New intelligence — a fresh indicator, a newly observed technique, a campaign disclosed by a partner organisation — needs to translate automatically into a specific, running hunt against an organisation’s actual environment, with no manual handoff step required to make that happen. And what a hunting team finds — an artifact that didn’t match any known indicator, a technique that resembles but doesn’t exactly match a documented campaign, a false lead that took time to rule out — needs to flow back into the intelligence layer automatically, so the next hunt starts smarter than the last one did, rather than every engagement beginning from the same static baseline.

IFC0 Intelligence Module — HUNT Bridge (CYBER-OPS)

IFC0’s HUNT Bridge module operates as a closed-loop operational record between IFC0 intelligence and HUNT operations — every relevant indicator or technique surfaced by IFC0 automatically seeds an active hunting hypothesis, and every discovery HUNT operators make flows back to refine IFC0’s intelligence picture in real time. Bundled exclusively for dual-stack clients running both platforms together, because the value of this module exists entirely in the connection between the two, not in either one alone.

An accurate report that nobody hunted against, and a skilled hunting team working from stale intelligence, produce the same outcome: a threat that was, technically, known about somewhere in the organisation, and acted on nowhere in time to matter.


메타데이터
post_id
d1c69c45b571
slug
the-report-nobody-hunted-fiive-eyes-d1c69c45b571
url
https://medium.com/@fiiveeyes/the-report-nobody-hunted-fiive-eyes-d1c69c45b571
canonical_url
https://medium.com/@fiiveeyes/the-report-nobody-hunted-fiive-eyes-d1c69c45b571
author_url
https://medium.com/@fiiveeyes
status
ok
fetched_at
2026-08-03 04:45:28